Security at RecordX
Controls in place today
Encryption in transit
All client connections use TLS 1.2 or higher. HTTP redirects to HTTPS. Older protocols are rejected at the edge.
Encryption at rest
Audio, transcripts, summaries, and account data are encrypted at rest with industry-standard symmetric encryption managed by our cloud provider's key service.
Managed identity
Sign-in is handled by a managed identity provider (AWS Cognito). RecordX never stores passwords itself. Session tokens are short-lived and refreshed through a dedicated refresh flow.
Least privilege
Internal services run with scoped IAM permissions. Client applications hold short-lived session tokens and reach storage only through signed, time-limited URLs issued by our backend.
Bot-free capture
RecordX records audio locally on your device and uploads it directly to your account. Nothing extra joins the meeting; no third-party recording service sees the audio in transit.
Separated environments
Development and production run as fully isolated AWS accounts and stacks. Production data is never copied into development.
Hosting and data location
RecordX runs on AWS in the eu-central-1 region (Frankfurt). Audio, transcripts, summaries, and
account data stay in that region; we do not copy recordings across regions. Israeli users' data is covered by
the EU-Israel adequacy framework.
Our infrastructure provider (AWS) maintains independent third-party attestations for the underlying platform, including SOC 1 / SOC 2 / SOC 3, ISO 27001 / 27017 / 27018, and CSA STAR. RecordX inherits that posture for the platform layer, not for the application layer above it.
Data retention and deletion
You control your data. Every recording, transcript, and summary can be deleted from the app at any time. Deleting your account permanently removes your recordings, transcripts, and summaries within 30 days. Incomplete uploads that never finish are reaped automatically.
We do not use your audio, transcripts, or summaries to train AI models. We do not sell your data. See the privacy policy for full details on what we store and for how long.
Operational practices
- Every production code change goes through review before merge.
- Application code, container images, and dependencies are scanned continuously for known vulnerabilities.
- Access to production systems is scoped and audit-logged.
- Incident-response runbooks exist and are exercised.
What we do not yet offer
Where you would need to know the gaps for a procurement review.
- SOC 2 Type II report. RecordX has not yet completed an independent SOC 2 audit. Our underlying cloud provider holds SOC 2, but the application layer does not. On the roadmap.
- Enterprise SSO / SAML / SCIM. Sign-in today is email + password or Google. Enterprise SSO and directory provisioning are on the roadmap.
-
Custom data residency. All accounts live in
eu-central-1. We do not currently offer per-customer region choice.
Contact us for a security review
Email security@recordx.io for security questions, suspected vulnerabilities, procurement reviews, or to request our security controls documentation. We respond within two business days. For anything else, use the contact form.
Related reading: detailed security page, compliance overview, GDPR, SOC 2, HIPAA.